There are 4 open security issues in bullseye.
2 important issues:
- CVE-2026-66140:
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
- CVE-2026-66141:
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
2 issues postponed or untriaged:
- CVE-2026-40686:
(postponed; to be fixed through a stable update)
In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.
- CVE-2026-40687:
(postponed; to be fixed through a stable update)
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.